Privacy Policy
The short version: we collect the minimum a free account needs, we never sell or share personal data, your AI conversations never reach us — only tool calls do — and one email deletes everything. The rest of this page is the detail behind those four claims, not exceptions to them.
What sign-up collects, and why
Creating an account asks for exactly five things. Here is each one and the single reason it exists. Nothing else is collected at sign-up, and no field on this list is used for a second, unstated purpose.
| Field | Why we ask |
|---|---|
| Signing in, the verification code, and password recovery. Also the address we answer when you write to us. Not used for marketing — there is no marketing list. | |
| Password | Proving you are you. The sign-in page uses SRP, so your password is never transmitted in readable form and we never see it — the account system (AWS Cognito) stores only a verifier it can check a proof against. |
| Name | So the hub can address you, and so evidence cards you generate can carry your byline. Use any name you like. |
| Credential | Self-reported — RD/RDN, nutrition coach, researcher, or none. It tells us who the instrument is actually serving and helps sequence MCP early access. We never verify it and never publish it. |
| Intended use | One line on what you want the tools for. Same purpose as credential: shaping the product, nothing else. |
What using the hub stores
Your account row holds the fields above plus what you do in the app: the diseases you follow, your in-app notifications, and your settings. That lives in our database (AWS DynamoDB), keyed to your account, readable by no other user. Your browser holds your sign-in session in localStorage — that is the only thing this site puts in your browser. No marketing cookies, no cross-site tracking, and no third-party analytics: none is installed. If an analytics tool is ever added, this policy changes first and says so.
The MCP server sees less than you might think
When your AI assistant (Claude, ChatGPT, or any MCP client) calls our tools, the server receives the tool call and its arguments — nothing else. An ingredient name ("Red 3"), a claim query, search text, a filter. It never receives the surrounding conversation, your chat history, your files, or anything your assistant knows about you or your clients. That is how the Model Context Protocol works, and it is the design we want.
Tool-call queries may be logged, with timestamps and network metadata, for one purpose: keeping the server reliable and detecting abuse. Those logs are kept for up to 30 days and then deleted. They are not used to build profiles, not joined to your account history, not sold, not shared.
Please don't put client-identifying health information into tool queries. "Is aspartame a carcinogen?" works exactly as well as the same question with a name and a diagnosis attached. Nutrition questions do not need your client's identity — and we do not want it in our logs. If you are a practitioner, your professional confidentiality obligations apply to what you type; keep identities out and there is nothing here to protect.
Standardization scorecard
The hub is adding a self-reported scorecard: questions about your practice workflow whose answers you can choose to save to your profile. Three rules are fixed before the feature ships. It is self-reported — your answers, entered by you, never inferred. It is deletable — edit or remove any answer, or the whole scorecard, at any time. And if we ever publish "state of nutrition practice" statistics from it, they are anonymized counts across many profiles — never an individual profile, never an answer with a name or credential attached, and never published at a granularity where a count could identify a person.
Who processes the data
The service runs on Amazon Web Services in US regions: Cognito holds accounts, DynamoDB holds profile data, Lambda and API Gateway serve the account API, S3 and CloudFront serve the site. AWS processes this data under our instructions as a processor; it does not get to use it for its own purposes. That is the whole list — there is no data broker, ad network, or analytics vendor in the chain.
Retention and deletion
Account data is kept while your account exists. Delete your account from the Profile page — that removes your profile, follows, notifications and scorecard answers — or email paulmorf@morfengineering.tech and we complete deletion within 30 days. Operational logs (site, API and MCP) age out within 30 days on their own. Backups age out on the same schedule.
Your rights, our contact
Ask what we hold about you, ask for a correction, or ask for deletion: paulmorf@morfengineering.tech. We do not sell personal data, we do not share it for advertising, and the only disclosure we will ever make without your instruction is one the law compels — and then only what is compelled. This policy is versioned and dated; a material change is announced in-app before it takes effect.
Terms of Use
The service, and what it costs
NutriCollective is the evidence hub at nutri-collective.mealcoach.ai and the nutrition-evidence MCP server. Both are free — no card, no metering, no billing. There are no payment terms in this document because there is nothing to pay. If a paid tier ever exists, it will come with its own terms and an explicit opt-in; nothing converts silently.
Your account
Use a real email (the verification code has to reach you), keep your password to yourself, and keep one account per person. You can close your account at any time from the Profile page, and closing it deletes your data as described in the policy above.
Acceptable use
- Don't break the instrument. No credential stuffing, no scraping the account API, no deliberately flooding the MCP server. Rate limits exist; respect them.
- Don't strip provenance. Every answer carries its register name and version. Quoting the answer without its register — or editing an evidence card to add a claim, grade or PMID — falsifies what makes this instrument worth using.
- Don't misrepresent output. A found: false is not a finding of safety or of harm, an unverified citation is not a verified one, and this site's name may not be used to imply endorsement of a claim it does not grade.
What the answers are — and are not
This is an independent research instrument: versioned registers, honest gaps, stated limits. The not-medical-advice disclaimer in the footer of every page is part of these terms — the tools inform professional judgment, they do not replace it. If you are a practitioner, decisions about a client remain yours, and so do your confidentiality obligations, including what you type into tool queries.
No warranty, honest liability
The service is provided as-is, in early access, while the registers grow. It can be wrong, incomplete or down, and we say so on the box rather than in fine print. To the extent the law allows, our total liability to you is limited to what you have paid us for the service — which is zero. Nothing in these terms limits liability the law does not allow us to limit.
Changes and housekeeping
We may change or pause features while the platform is in early access; material changes to these terms are announced in-app before they apply. Site content and registers are © Morf Engineering Inc. — quote with attribution. Your scorecard answers remain yours. These terms are governed by United States law. Questions: paulmorf@morfengineering.tech.